Unidirectional Data Transfer System with Bilateral Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security devices, such as firewalls, do not provide sufficient protection against unauthorized data disclosure in high-security computer networks, and existing unidirectional data transfer systems lack the ability to implement different security policies and protocols for bilateral communication.

Innovation Solution

Implementing bilateral communication using multiple one-way data links, where each link is separately administered and configured to enforce unidirectional data flow, allowing for different security policies, protocols, and data filtering processes in opposite directions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls are used for network security, then basic data protection is provided, but they do not provide sufficient protection against unauthorized data disclosure in high-security networks

Engineering Contradiction:
Improvenetwork security protectionVSAvoidunauthorized data disclosure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the communication system into separate unidirectional data links for each direction of data flow. Each link is independently secured with its own security policies and protocols, ensuring that a breach in one direction does not compromise the other direction. This segmentation provides robust protection against unauthorized data disclosure by isolating security domains.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If unidirectional data transfer systems are used to prevent unauthorized data disclosure, then security is improved, but the ability to implement different security policies and protocols for bilateral communication is lost

Engineering Contradiction:
Improveunauthorized data disclosure preventionVSAvoidsecurity policy configuration flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system segments bilateral communication into separate unidirectional links, each capable of having its own security policies and protocols. This allows the secure network to enforce strict security measures for incoming data while allowing the unsecured network more flexible data transfer capabilities, thus maintaining both security and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security policies and protocols are applied to different directions of data flow. The secure network side can implement stringent security measures for data entering the secure domain, while the unsecured network side can use simpler protocols for data leaving the secure domain. This local differentiation of security quality enables versatile security configuration.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple one-way data links are used for bilateral communication with different security policies, then network security is enhanced, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transfer system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces data transfer applications as intermediaries that manage the complexity of multiple unidirectional links. These applications handle security policy enforcement, protocol conversion, and data routing between the secure and unsecured networks, abstracting the complexity from the overall system architecture while maintaining enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9088539B2Data transfer system
Publication Date: 2015.07.21 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9088539B2 patent drawing
  • US9088539B2 patent drawing
  • US9088539B2 patent drawing

AI summary

A data transfer system comprising a first node, a second node, and a first one-way link for unidirectional transfer of data from the first node to the second node. The first node is configured to receive data and to allow transfer of the data to the second node via the first one-way link only if there is a match between a characteristic of the received data and an entry in a first predefined configuration file. The system may also include a second one-way link for unidirectional transfer of second data from the second node to the first node. The second node is configured to receive the second data and to allow transfer of the second data to the first node via the second one-way link only if there is a match between a characteristic of the second data and an entry in a predefined configuration file.